16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
- Posted on October 8, 2026
- By The Hacker News
- 1 Views
- 1 min read
Security researchers have uncovered a sophisticated phishing campaign targeting cryptocurrency users through fraudulent browser extensions. Sixteen malicious add-ons disguised as legitimate Rabby and OKX wallet applications have been distributed on Firefox, designed to harvest sensitive authentication data. When users attempt to import their wallets, these fake extensions intercept and exfiltrate recovery phrases and private keys, compromising entire cryptocurrency portfolios. This attack highlights the critical importance of verifying extension sources and implementing additional security layers.
Summary auto-generated by AI from the original publisher's content. Editorial standards.